Sungrow welcomes security researchers, customers, partners, and other stakeholders to report potential security vulnerabilities in our products and services. Your feedback helps us continuously improve product security and better protect our customers and business operations.
If you discover any security vulnerabilities within Sungrow’s products or services, please submit your vulnerability report via the channel below.
Submission Channel
Email:psirt@sungrowpower.com
To protect the confidentiality of vulnerability details, PGP-encrypted submission is highly recommended.
PGP Public Key:48DC700294BC32C1
Key Fingerprint:AEF29AB58E8626351AE8913448DC700294BC32C1
Download Link:https://keys.openpgp.org/search?q=AEF29AB58E8626351AE8913448DC700294BC32C1
Privacy Notice
When submitting a vulnerability report by email, Sungrow will process your contact details and personal data within your message/attachments to assess & handle the report, communicate remediation, coordinate disclosure and meet legal obligations.
Please provide only vulnerability-proof necessary information. Remove/mask unrelated personal data (especially data of third parties). Do not include passwords, private keys or active credentials.
Without your separate consent, your contact data will not be used for marketing or public acknowledgement attribution. Personal data will be retained only for the period necessary for above purposes.
For details of personal data handling and your rights, refer to the Sungrow Website Privacy Policy.
Information to Include
To help us efficiently analyze and validate reported vulnerabilities, please provide as much of the following information as possible:
Product name and model
Software, firmware, or system version
Detailed description of the vulnerability
Potential impact and risk assessment
Steps required to reproduce the vulnerability
Test environment information
Proof-of-Concept (PoC) code, test scripts, logs, screenshots, or other supporting materials
Contact information (optional)
The more complete the information you provide, the more efficiently we can evaluate and address the reported issue.
Vulnerability Report Template & Anonymous Submission
You may refer to the Vulnerability Report Template to structure your report.
Anonymous submissions are accepted. Please note, however, that if no valid contact information is provided, we may be unable to communicate with you regarding validation results, remediation progress, or other follow-up matters.
Response Commitment
Upon receiving a vulnerability report, the Sungrow PSIRT will initiate analysis and validation as soon as possible.
Under normal circumstances:
Receipt of your report will be acknowledged within 2 days.
Initial assessment and validation results will be provided within 7 days.
We will keep reporters informed of significant progress throughout the vulnerability handling process. For complex vulnerabilities or vulnerabilities affecting multiple products, additional time may be required for thorough investigation and remediation.
After You Submit
All reports are handled under Sungrow's standardized PSIRT workflow: Reception → Assessment → Remediation → Disclosure → Improvement. See the Vulnerability Response Process tab for details.
For disclosure principles, confidentiality obligations, safe harbor provisions, and reporter recognition, please refer to our Vulnerability Disclosure Policy.





